ASP Simple Blog 3.0 - Arbitrary File Upload

EDB-ID:

10753

CVE:

N/A




Platform:

Multiple

Date:

2009-12-28


========================================================================================                  

| # Title    : ASP Simple Blog version 3.0 Upload shell Vulnerability                  |

| # Author   : indoushka                                                               |

| # email    : indoushka@hotmail.com                                                   |

| # Home     : Souk Naamane - 04325 - Oum El Bouaghi - Algeria -(00213771818860)       |

| # EDB-ID   :                                                                         |

| # CVE-ID   : ()                                                                      |

| # OSVDB-ID : ()                                                                      |

| # DAte     :16/12/2009                                                               |

| # Verified :                                                                         |

| # Web Site : www.iq-ty.com                                                           |

| # Published:                                                                         |

| # Script   : ASP Simple Blog version 3.0 Copyright (c) 2003-2006 www.8pixel.net      |

| # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)       |

| # Bug      : XSS                                                                     | 

======================      Exploit By indoushka       =================================

| # Exploit  : 

| 

| 1- http://127.0.0.1/simpleblog3/admin/includes/FCKeditor/editor/filemanager/upload/test.html

|

================================   Dz-Ghost Team   ========================================

Greetz : all my friend * Dos-Dz * Snakespc * His0k4 * Hussin-X * Str0ke * Saoucha * Star08 |

-------------------------------------------------------------------------------------------